Fun

News Feed - 2023-07-26 01:07:24

Tom Blackstone7 hours agoEra Lend on zkSync exploited for $3.4M in reentrancy attackThe lending app was drained of funds using a “read-only reentrancy” bug, a type of vulnerability that is often difficult for auditors to spot.1128 Total views3 Total sharesListen to article 0:00NewsJoin us on social networksLending app Era Lend on zkSync has been exploited for $3.4 million worth of crypto, according to a July 25 report from blockchain security firm CertiK. The attacker used a “read-only reentrancy attack” to drain the funds, which is a type of attack that interrupts a multi-step process and then causes it to continue after a malicious action has been performed. Specifically, a “read-only” reentrancy is one that does not update the state of a contract.#CertiKSkynetAlert

We are seeing reports that @Era_Lend has been exploited on zkSync

Total losses appear to be $3.4 million in a read only reentrancy attack

See more below https://t.co/h8xrjccE5i— CertiK Alert (@CertiKAlert) July 25, 2023


According to the report, the attacker drained funds in two separate transactions using the externally owned account 0xf1D076c9Be4533086f967e14EE6aFf204D5ECE7a. The attacker relied on a vulnerability in “the callback and _updateReserves function” to manipulate a contract into reporting old values that had not yet been updated.


Era Lend is a fork of the Syncswap project, and CertiK claimed that other projects based on Syncswap may also be vulnerable to the exploit.


On-chain sleuth and Twitter user Spreek reported that the Syncswap code allows a user to “burn, then callback before update_reserves is called,” causing the oracle to report incorrect values.in the syncswap LP tokens, one can burn, then callback before update_reserves is called. so the oracle uses an incorrect reserves value to calculate the price, resulting in an inflating oracle price. pic.twitter.com/0U7Vu7BzJM— Spreek (@spreekaway) July 25, 2023


Spreek also reported that the Era Lend team had acknowledged the attack and paused the protocol’s zkSync contracts to prevent further exploits.


Another blockchain investigator, known on Twitter as Saul, reported that the attack had affected stablecoin USDC+, which is issued by the Overnight Finance protocol. According to Saul, the Overnight team has acknowledged the exposure and has paused its own contracts as well. Over $261,000, or 7.86% of the total value of the collateral backing the stablecoin, may have been lost.


In a June 7 blog post explaining how read-only reentrancy attacks are carried out, pseudonymous blockchain investigator Officer’s Notes stated that these vulnerabilities are difficult for auditors to spot, since “Typically, auditors and bug hunters are only concerned with entry points that modify state when looking for reentrancy.”


To help alleviate this problem, Officer’s Notes recommends that auditors use specialized software to aid them in finding these vulnerabilities.


Era Lend runs on the zkSync network, a zero-knowledge proof Ethereum layer-2 rollup. In April, the network’s total value locked reached over $110 million. The network’s developers intend to create an ecosystem of interoperable chains called “Hyperchains” by the end of the year.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.# Blockchain# Cryptocurrencies# Security# Ethereum# Cybersecurity# Hacks# DeFiAdd reactionAdd reactionRelated NewsHow to actually spend your Bitcoin, ExplainedTwitter vs. Threads: Users are the real losersZero-knowledge tech development heats up amid bear marketCrypto hacks and exploits snatch over $300M in Q2 2023: ReportMultichain MPC bridge sees $100M+ outflows, sparking fears of exploitArbitrum-based Rodeo Finance exploited for second time, $1.5M stolen

News Feed

Weekend Bitcoin trading drops due to TradFi institutions and spot ETFs
Brayden Lindrea4 hours agoWeekend Bitcoin trading drops due to TradFi institutions and spot ETFsThe share of weekend BTC trading volume has been in decline since 2018 but has dropped considerably since the U.S. launch of
Ark Invest Expects Bitcoin to Become a Multitrillion-Dollar Market — Predicts BTC Price Could Reach $1.48 Million
Ark Invest Expects Bitcoin to Become a Multitrillion-Dollar Market — Predicts BTC Price Could Reach $1.48 Million Investment management firm Ark Invest says bitcoin is “li
Israel’s Securities Watchdog Seeks to Regulate Crypto Assets
Israel’s Securities Watchdog Seeks to Regulate Crypto Assets The body overseeing the securities market in Israel is taking steps to incorporate rules for digital assets into the
Amaka Nwaokocha1 hour agoAI companies commit to safe and transparent AI — White HouseThe Biden Administration emphasized the responsibility of AI companies to ensure their products are safe for use.832 Total views4 Tot
SEC Criticized for How It Regulates Crypto — Chair Gensler Says Most Crypto Tokens ‘Have Attributes of Securities’
SEC Criticized for How It Regulates Crypto — Chair Gensler Says Most Crypto Tokens "Have Attributes of Securities" The U.S. Securities and Exchange Commission (SEC) has been heav
Cointelegraph10 hours agoZero Barriers podcast series: Crypto adoption fueled by ZK-rollupsThe podcast series is produced in collaboration with StarkWare and explores the future of ZK-rollups as an Ethereum layer-2 solut
London-Based Cryptocurrency Exchange LBX Faces Compulsory Liquidation
London-Based Cryptocurrency Exchange LBX Faces Compulsory Liquidation London-based cryptocurrency exchange LBX is the latest digital asset trading venue to face critical difficul
‘Bank of Jamaica Will Roll Out Digital Jamaican Dollar in 2022,’ Says Prime Minister
"Bank of Jamaica Will Roll Out Digital Jamaican Dollar in 2022," Says Prime Minister According to an announcement from Jamaica’s Prime Minister Andrew Holness the Bank of Ja
Accounting Firm PWC’s Hong Kong Branch Purchases Land in The Sandbox Metaverse
Accounting Firm PWC"s Hong Kong Branch Purchases Land in The Sandbox Metaverse On Thursday, Pricewaterhouse Coopers’ (PWC) Hong Kong unit announced that it purchased a land
Canada needs to overhaul crypto regulations — Coinbase exec
Vince Quill6 hours agoCanada needs to overhaul crypto regulations — Coinbase execThe Canadian government has previously come under fire for undermining the economic freedom of its citizens and freezing crypto donations
Mawson Infrastructure Group Launches Bitcoin Mining Operation in Pennsylvania, Exits Australia
Mawson Infrastructure Group Launches Bitcoin Mining Operation in Pennsylvania, Exits Australia The bitcoin mining operation, Mawson Infrastructure Group, Inc., announced that the f
Mastercard Launches NFTs to Support Emerging Musicians Through Web3 Technologies
Mastercard Launches NFTs to Support Emerging Musicians Through Web3 Technologies According to Mastercard, the payments giant has launched non-fungible tokens (NFTs) that grant acce